Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents that OAuth tokens are stored on disk in `~/.mcporter/autosend/tokens.json` but does not warn that these credentials are sensitive bearer secrets. If another local user, backup system, logs, or malware can read that file, an attacker may reuse the tokens to access the user's AutoSend account and email campaign data without re-authenticating.
